PII-redacting proxy for LLM APIs.
308
A drop-in proxy that redacts PII and PHI out of LLM prompts before they leave your network. Requests destined for OpenAI, Azure OpenAI, Claude, Gemini, Vertex AI, Ollama, or Amazon Bedrock are sent first to Philter, which redacts sensitive text per your policy, then forwarded to the provider. Responses can optionally be scanned on the way back.
Point your client at the proxy instead of the provider. The API stays the same, only the hostname changes.
docker run -p 8080:8080 \
-v $(pwd)/config.yaml:/app/config.yaml:ro \
-e PHILTER_PROXY_CONFIG=/app/config.yaml \
philterd/philter-ai-proxy
Start from config.example.yaml and set philter.endpoint to your Philter instance. No keypair is baked into the image: set listen.cert and listen.key, or listen.devSelfSignedCert: true for local testing only.
Detection is probabilistic and configurable. The proxy is designed to reduce how much sensitive data reaches a provider; validate its output against your own data. It is a redaction layer, not an AI gateway, and runs alongside one such as LiteLLM or Kong AI Gateway. Text conversations only: multipart/form-data uploads are rejected.
Apache 2.0. Source, docs, and issues: github.com/philterd/philter-ai-proxy | documentation
Content type
Image
Digest
sha256:355a84c7a…
Size
17.7 MB
Last updated
about 1 month ago
docker pull philterd/philter-ai-proxy